Custom MCP Environment Variable Bypass in Flowise by FlowiseAI
CVE-2026-58057
Key Information:
Badges
What is CVE-2026-58057?
Flowise versions prior to 3.1.3 suffer from a vulnerability due to improper validation of Custom MCP standard input/output environment variables against a denylist. The case-sensitive nature of the comparison allows an authenticated user to exploit this flaw on Windows systems where environment variables are case-insensitive. By supplying 'node_options', an attacker can bypass the NODE_OPTIONS entry in the denylist. This enables the execution of arbitrary code within the Flowise server context, posing a significant security risk.
Affected Version(s)
Flowise 0 < 3.1.3
Flowise 3.1.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
